You currently have javascript disabled. Several functions may not work. Please re-enable javascript to access full functionality.

Register a free account to unlock additional features at BleepingComputer.com

Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

HJT Log--Viperguts

Hi, every 8 minutes or so my avant browser opens the hotoffers website. I have a fake warning message "Error 317 Microsoft Windows Security Warning ect ect " My homepage is now set to hotoffers. This does not effect my Firfox browser though. Sometimes my computer freezes and when I restart my background is sort of pixeled or not clear. I don't know is my computer freezing and background have anything to do with this though. Also, I recently did all my windows updates. Here is my log. Thanks in advance.

BC AdBot (Login to Remove)

Download Silent RunnersUnzip it to a permanent folder.Start SilentRunners.vbsWhen your antivirus is giving an alert, do not block this. Allow the script.Copy and paste the content of the txtfile you get afterwards in your next reply.

Download Killbox
Click killbox.exe.
Select the option "Delete on reboot".
In the field "Full Path of File to Delete" copy and paste next:

C:\WINDOWS.000\System32\param32.dll

Choose the option: "unregister dll before deleting"
Then press the button that looks like a red circle with a white X in it.
Killbox will tell you that all listed files will be deleted on next reboot.. Click YES
When it asks if you would like to Reboot now, click YES
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.

Download Silent RunnersUnzip it to a permanent folder.Start SilentRunners.vbsWhen your antivirus is giving an alert, do not block this. Allow the script.Copy and paste the content of the txtfile you get afterwards in your next reply.

----------This report excludes default entries except where indicated.To see *everywhere* the script checks and *everything* it finds,launch it from a command prompt or a shortcut with the -all parameter.----------